Skip to content

chore: maintain 0.1 on release/0.1 and publish its patches under release-0.1 - #56

Merged
yomybaby merged 2 commits into
mainfrom
chore/release-lines
Oct 2, 2026
Merged

yomybaby merged 2 commits into
mainfrom
chore/release-lines

Conversation

@yomybaby

@yomybaby yomybaby commented Oct 2, 2026

Copy link
Copy Markdown
Member

Summary

main moved to 0.2, but apps still on 0.1 need hotfixes and patch releases. Today the publish workflow picks the dist-tag from the version alone (prerelease → next), so a 0.1 hotfix released as-is would pull next back from 0.2.0-alpha.15 to 0.1.

  • scripts/dist-tag.mjs (+ src/distTag.test.ts): compares the version being published with main's package.json.
    • main's line → next (prerelease) / latest (plain), unchanged behaviour
    • an older line → release-<line> (e.g. release-0.1); never touches next / latest
    • a line ahead of main → refused
    • release-0.1 is not a valid semver range, so npm accepts it as a dist-tag (0.1 would be rejected)
  • publish.yml: both jobs use the script (fetches origin main to read its version).
  • ci.yml: also runs on pushes to release/**.
  • README: new Versions section (0.2 on main via @next, 0.1 on release/0.1 via @release-0.1, where 0.1 fixes go). Install now names @next — latest still points at 0.1.0-alpha.23, so the bare command installed 0.1.
  • CONTRIBUTING: Releasing split into From main and Patching an older line (cutting a release branch, fix/cherry-pick policy, versioning, gh release create --target release/0.1 --prerelease --latest=false, dist-tag check, recording the entry on main).

The release/0.1 branch exists (cut from v0.1.0-alpha.23). Since a release runs the workflow from the tagged commit, the branch gets the same rule in its own PR: #55.

0.1 patch versioning: 0.1 never had a plain release, so patches continue 0.1.0-alpha.24, … which ^0.1.0-alpha.N ranges already accept. A line with a plain release patches as 0.2.1.

Verification

  • pnpm run verify — passes (typecheck, lint, format, boundary, theme, test, build, pack, integration)
  • node scripts/dist-tag.mjs 0.1.0-alpha.24 0.2.0-alpha.15 → release-0.1; 0.2.0-alpha.16 0.2.0-alpha.15 → next

…ase-0.1

main moved to 0.2, but apps still on 0.1 need fixes. The publish workflow
picked the dist-tag from the version alone (prerelease -> next), so a 0.1
hotfix released as-is would have pulled `next` back from 0.2 to 0.1.

scripts/dist-tag.mjs now compares the version with main's: main's line
publishes under next/latest as before, an older line under
release-<line>, and a line ahead of main is refused. Both publish jobs use
it, and CI also runs on pushes to release/** branches.

README gains a Versions section (0.2 on main via @next, 0.1 on
release/0.1 via @release-0.1) and its Install line names @next, since
latest still points at 0.1 until 0.2.0. CONTRIBUTING documents cutting a
release branch, fixing, versioning, releasing and recording an older
line's patch.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Independent mutable-main lookups can assign inconsistent dist-tags across registries, and one release instruction overstates validation.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Adds safe npm dist-tag routing for maintained release lines.

Changes:

  • Adds and tests release-line dist-tag selection.
  • Updates publishing and release-branch CI workflows.
  • Documents 0.1 maintenance and release procedures.
File Description
scripts/​dist-tag.mjs Implements dist-tag selection.
scripts/​dist-tag.d.mts Declares script types.
src/​distTag.test.ts Tests release routing.
.github/​workflows/​publish.yml Uses dynamic dist-tags.
.github/​workflows/​ci.yml Enables release-branch CI.
README.md Documents supported versions.
CONTRIBUTING.md Documents maintenance releases.
CHANGELOG.md Records the policy change.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/publish.yml Outdated
Comment thread CONTRIBUTING.md Outdated
Address ready-gate review: a separate dist-tag job reads main once and
both publish jobs take its outputs, so the two registries cannot disagree
if main moves to a new line between them. The documented gh release
command no longer uses a <placeholder> the shell reads as redirection.
@yomybaby

yomybaby commented Oct 2, 2026

Copy link
Copy Markdown
Member Author

Ready-gate agent review (Opus) — blocking issues only

NO BLOCKING ISSUES (reviewed at 0d03096).

Copilot: reviewed — its findings were fixed in c046889 after both reviews and verified locally (format check + dist-tag tests + workflow YAML parse), not re-reviewed.

@yomybaby
yomybaby marked this pull request as ready for review October 2, 2026 06:26
@yomybaby
yomybaby merged commit a90e457 into main Oct 2, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants